OWASP Security Shepherd Project - Session Management Challenge 7 (Session Management Challenge)

Challenge

Solution

     Challenge 7 is quite similar to Challenge 6, but there is no SQLi in Security Question.

     I really don't think people could pass challenge this without cheating.

     There are a lot of flowers in the world & the answer for root user is "Franklin Tree" which is not a common flower...

     However, I think what people should learn here is to make sure your security question should be good enough!

    For example, if the question here is "What is your favorite brand of mobile phone?"
An attacker could definitely enumerate all the major brands in the world and use tool to try them all. (Ex: BurpSuite -> Intruder to import a list of brands.)

    In addition, if in the question setting panel, the application prepares few answer for user to select, then the scenario will be even easier. (Ex: "What is your favorite brand of mobile phone?" -> Select the following "Apple", "HTC", "Samsung", "Huawei".)








留言

張貼留言

Welcome to share your comments or questions : -)
Enjoy life!

The Hottest Articles

OWASP Security Shepherd Project - My Practice & Solutions

OSCP回顧 & 準備建議

OWASP Security Shepherd Project - SQL Injection 3 (Injection Challenge)